Re: [clamav-users] Potentially False Positive, but I lost the file!

2017-01-21 Thread Joel Esler (jesler)
This open source, free, project is made up of its community. While we provide most of the detection and underlying systems that support the project and community, the ton of community based signatures we ingest and publish are the real help. Obviously you are unhappy and have been unhappy with

[clamav-users] clamAV: Re: Re: problem in DB update

2017-01-21 Thread Cedric Bhihe
Hi Harald: I'm happy. Thank you for the pointers. Hi Al: I added the additional mirrors because I use the box in question to experiment with Tor and so its exit nodes' geolocalization will change if I log in and out or when I restart network services. My mistake in that was that I did not rea

Re: [clamav-users] Potentially False Positive, but I lost the file!

2017-01-21 Thread Joel Esler (jesler)
-- Sent from my iPhone > On Jan 21, 2017, at 11:16 AM, Alain Zidouemba > wrote: > > Antonio, > > Unfortunately, I can't find any record of us having ever published > Win.Trojan.Agent-18112140. > Could the name of the signature that caused the FP be slightly different? > > Alain > > On Sat,

Re: [clamav-users] Potentially False Positive, but I lost the file!

2017-01-21 Thread Joel Esler (jesler)
Groach -- Sent from my iPhone > On Jan 21, 2017, at 10:43 AM, Groach > wrote: > > I would put my house on that it was a false positive 100%. Reasons for > saying so: > > 1, It was a windows installation CD > 2, Its a file nearly 20 years old > 3, Clam signatures couldnt detect water in a

Re: [clamav-users] Potentially False Positive, but I lost the file!

2017-01-21 Thread Antonio Piccolomini d'Aragona
Great! I am glad I could help! Thanks for the support! Wishes Antonio 2017-01-21 18:50 GMT+01:00 Alain Zidouemba : > The signature Win.Trojan.Agent-1812140 is causing a FP on an Italian > Microsoft Office file from the mid-90s. I'm dropping the signature now. > > Thanks Antonio for taking the ti

Re: [clamav-users] Potentially False Positive, but I lost the file!

2017-01-21 Thread Alain Zidouemba
The signature Win.Trojan.Agent-1812140 is causing a FP on an Italian Microsoft Office file from the mid-90s. I'm dropping the signature now. Thanks Antonio for taking the time to report this despite no longer having access to the file that caused the FP. -Alain On Sat, Jan 21, 2017 at 11:38 AM,

Re: [clamav-users] clamAV: Re: problem in DB update

2017-01-21 Thread Reindl Harald
Am 21.01.2017 um 17:49 schrieb Cedric Bhihe: Hallo Harald, What I am writing about is that in the past few weeks, root has been getting a daily email with exactly the content you quoted. It had not always been so before. In other words I did not use to get a straight 100% update, say a year ago,

Re: [clamav-users] clamAV: problem in DB update

2017-01-21 Thread Al Varnell
As already stated, it would appear that everything was working just fine and changing the mirror settings was totally unnecessary. There is no need need to add any country settings at all as freshclam will choose the correct ones automatically based on where you are. Adding country specific

[clamav-users] clamAV: Re: problem in DB update

2017-01-21 Thread Cedric Bhihe
Hallo Harald, What I am writing about is that in the past few weeks, root has been getting a daily email with exactly the content you quoted. It had not always been so before. In other words I did not use to get a straight 100% update, say a year ago, but rather an update process sufficiently long

Re: [clamav-users] Potentially False Positive, but I lost the file!

2017-01-21 Thread Antonio Piccolomini d'Aragona
Actually, there is a 1 less. It is Win.Trojan.Agent-1812140 (I looked in my Mac Cronology...where I looked for some ways to fix) 2017-01-21 17:16 GMT+01:00 Alain Zidouemba : > Antonio, > > Unfortunately, I can't find any record of us having ever published > Win.Trojan.Agent-18112140. > Could the

Re: [clamav-users] clamAV: problem in DB update

2017-01-21 Thread Reindl Harald
Am 21.01.2017 um 17:22 schrieb Cedric Bhihe: The mail sent to root when the daily DB update process has completed always is : ClamAV update process started at Thu Jan 19 13:00:01 2017 main.cvd is up to date (version: 57, sigs: 4218790, f-level: 60, builder: amishhammer) Downloading

Re: [clamav-users] Potentially False Positive, but I lost the file!

2017-01-21 Thread Antonio Piccolomini d'Aragona
Yes, probably it is...as I said, I formatted and lost all the infos. 2017-01-21 17:16 GMT+01:00 Alain Zidouemba : > Antonio, > > Unfortunately, I can't find any record of us having ever published > Win.Trojan.Agent-18112140. > Could the name of the signature that caused the FP be slightly differe

[clamav-users] clamAV: problem in DB update

2017-01-21 Thread Cedric Bhihe
Hello, I run clamAV 0.99.2 on Ubuntu 14.04 (kernel 4.4.0-62-generic #83) direct from cli and have automated DB updates configured. I do not use clamTK at all as I do not usually run a desktop gui on that box. My question is about DB updates. I have not had one update in the past 4 or 5 weeks. I

Re: [clamav-users] Potentially False Positive, but I lost the file!

2017-01-21 Thread Alain Zidouemba
Antonio, Unfortunately, I can't find any record of us having ever published Win.Trojan.Agent-18112140. Could the name of the signature that caused the FP be slightly different? Alain On Sat, Jan 21, 2017 at 9:07 AM, Antonio Piccolomini d'Aragona < antpiccda...@gmail.com> wrote: > Hi, > I'm writ

[clamav-users] Potentially False Positive, but I lost the file!

2017-01-21 Thread Antonio Piccolomini d'Aragona
Hi, I'm writing for the following problem. After sudo freshclam, I had a scan of my system (UBUNTU 12.04 LTS) by sudo freshclam -r. ClamAv detected an infection relative to an ISO built from a Windows 95 installation CD. The signaled virus was said to be a Win.Trojan.Agent-18112140. Previous scans

[clamav-users] threatcenter.crdf.fr gone?

2017-01-21 Thread sebast...@debianfan.de
Is the threatcenter gone ? Are there alternatives? tnx Sebastian ___ clamav-users mailing list clamav-users@lists.clamav.net http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users Help us build a comprehensive ClamAV guide: https://github.com/